O-RAN Network Element Authentication via Dynamic Protocol Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing diversity of network elements (NEs) in radio access networks (RANs) due to multi-vendor environments poses challenges in efficiently and securely authenticating NEs with different authentication capabilities, particularly in Open RAN (O-RAN) systems.
Innovation Solution
The implementation of a system that allows non-virtual machine (VM) based NEs to perform certificate enrollment via a Certificate Authority (CA) server in a secure and authenticated manner, supporting both fully automated and semi-automated enrollment methods to accommodate NEs with varying authentication capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication methods are used in multi-vendor environments, then vendor-specific network elements can be authenticated, but the system cannot efficiently authenticate NEs with different authentication capabilities
Solution Approach 1:
The authentication system dynamically adapts its behavior based on the capabilities of the network element being authenticated. The system determines whether an NE supports IEEE 802.1x authentication and automatically selects the appropriate authentication method (802.1x for capable NEs, DHCP-based for non-capable NEs), making the system flexible and adaptable to different authentication capabilities without requiring a completely different authentication architecture for each NE type
Solution Approach 2:
The authentication process is segmented into distinct paths based on NE capabilities. One path handles NEs with IEEE 802.1x support through switch-based 802.1x authentication, while another path handles NEs without 802.1x support through DHCP-based authentication. This segmentation allows each authentication method to be optimized independently for its target NE type, resolving the contradiction between versatility and complexity
2Reliability
If IEEE 802.1x authentication is implemented for all NEs, then security is improved, but NEs without 802.1x support cannot be authenticated
Solution Approach 1:
The system introduces an intermediary authentication mechanism (DHCP-based authentication) that bridges the gap between NEs without 802.1x support and the security requirements of the network. This intermediary method allows non-802.1x capable NEs to be authenticated securely through the DHCP protocol, while 802.1x-capable NEs continue to use the more secure 802.1x authentication, thus maintaining both security and compatibility
3Reliability
If manual certificate enrollment is used for non-VM based NEs, then authentication capability is achieved, but deployment time and complexity increase
Solution Approach 1:
The system enables self-service automated certificate enrollment for non-VM based NEs through the DHCP authentication process. When an NE without 802.1x support connects to the network, the DHCP server automatically initiates the certificate enrollment process, retrieves the necessary certificates, and configures them on the NE without requiring manual intervention. This automated self-service approach maintains secure certificate-based authentication while dramatically reducing deployment time and operational complexity
Data Source
AI summary
A system, method and device for enhanced authentication of network elements are provided. The device may be configured to: obtain device information from a network element, transmit the obtained device information to a storage device in order to determine whether the network element supports authentication in accordance with a first authentication protocol, based on determining that the network element supports the authentication in accordance with the first authentication protocol, facilitate authentication of the network element with a first authentication server configured to perform the authentication in accordance with the first authentication protocol, and based on determining that the network element does not support the authentication in accordance with the first authentication protocol, facilitate the authentication of the network element with at least one server configured to perform authentication in accordance with a second authentication protocol.


